SAP HANA XS Advanced Model User Account and Authentication Service Open Redirect Vulnerability

Vulnerability

A vulnerability in the User Account and Authentication service for SAP HANA extended application services, advanced model, allows an unauthenticated attacker to create a malicious link that, when clicked by a victim, redirects the browser to a harmful site. This exploitation takes advantage of inadequate validation of redirect URLs. Successful exploitation could lead to a limited impact on the system's confidentiality, integrity, and availability.

Impact

Exploitation of this vulnerability could cause a limited impact on the confidentiality, integrity, and availability of the system.

Remediation

Users are advised to review and implement the SAP Security Note related to this vulnerability, available through the SAP Security Patch Day.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
1.7
exploitability
6.4
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.